Browser-local configuration

Scanner settings

Preferences stay in this browser's localStorage. No preference cookie is used. Extended discovery still requires fresh authorization confirmation for every scan.

New scan

Scan target

HTTP/HTTPS only Read-only access
Read-only mode: this source IP can view shared completed reports but cannot start scans.
Scan profile
All included checks
  • DNS and mail: A, AAAA, CNAME, NS, MX, DNSSEC, CAA, SPF, DMARC, MTA-STS, TLS-RPT, and neutral record-count inventory.
  • HTTP transport: endpoint reachability, HTTP-to-HTTPS redirect, downgrade detection, response status, redirects, HTTP version, caching, compression, and delivery telemetry.
  • TLS: certificate chain, hostname, validity dates, expiry, negotiated protocol, cipher, issuer, and SAN count. Certificate-provider choice is neutral inventory.
  • Headers: HSTS, CSP, frame protections, MIME sniffing, Referrer-Policy, Permissions-Policy, COOP, CORP, COEP, and server/framework disclosure.
  • Cookies and CORS: Secure, HttpOnly, SameSite, __Host- rules, arbitrary origins, and credentialed CORS.
  • HTML security: mixed content, password/form transport, cross-origin forms, third-party SRI, source-map hints, and generator disclosure.
  • Document quality: doctype, html/head/body, language, title, charset, viewport/zoom, h1/main, image alt text, description, canonical URL, Open Graph, Twitter/X card, and site icon.
  • Disclosure and public files: RFC 9116 security.txt, robots.txt, and sitemap.xml.
  • Visual preview: isolated 1440×810 screenshot using DNS-pinned, same-origin-only browser traffic without credentials.
  • Coverage matrix: authentication, authorization, session, injection, XSS, APIs, cloud, business logic, monitoring, and other unobservable controls are explicitly marked Not tested.
All additional checks
  • Includes every non-invasive check above.
  • Sensitive-file signatures: /.git/HEAD, /.env, /phpinfo.php, /server-status, /.svn/entries, and /.DS_Store.
  • Public manifests: /composer.json and /package.json.
  • API documents: /openapi.json and /swagger.json.
  • HTTP methods: reflected TRACE behavior and OPTIONS advertisement of PUT, DELETE, or CONNECT.
  • Excluded: login-based testing, injection, brute force, port scanning, denial of service, exploitation, and broad crawling.

This source IP (216.73.216.25) has read-only access. A shared report link remains viewable.

What this does not prove

Black-box automation cannot establish secure authorization, authentication, business logic, source code, dependencies, cloud configuration, or authenticated API behavior. Report marks these areas Not tested instead of guessing.